Date: Wed, 1 Jun 2011 21:38:44 -0400 From: Ryan Steinmetz <rpsfa@rit.edu> To: FreeBSD-gnats-submit@FreeBSD.org, freebsd-ports-bugs@FreeBSD.org Subject: Re: ports/157513: [update] net/samba35 to 3.5.8 Message-ID: <20110602013844.GA30119@fast.rit.edu> In-Reply-To: <201106020000.p5200Jc1066550@freefall.freebsd.org> References: <201106012352.p51Nq97U047241@red.freebsd.org> <201106020000.p5200Jc1066550@freefall.freebsd.org>
next in thread | previous in thread | raw e-mail | index | archive | help
--FL5UXtIhxfXey3p5 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline vuxml entry for DoS condition, if appropriate. --FL5UXtIhxfXey3p5 Content-Type: text/x-diff; charset=us-ascii Content-Disposition: attachment; filename="samba-vuxml.diff" --- vuln.xml.orig 2011-05-26 09:54:07.000000000 -0400 +++ vuln.xml 2011-06-01 19:33:58.000000000 -0400 @@ -34,6 +34,34 @@ --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="0b1173ed-8ca2-11e0-89b4-001ec9578670"> + <topic>samba -- Denial of service - memory corruption</topic> + <affects> + <package> + <name>samba34</name> + <name>samba35</name> + <range><lt>3.4.12</lt></range> + <range><lt>3.5.7</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <blockquote cite="http://xforce.iss.net/xforce/xfdb/65724"> + <p>Samba is vulnerable to a denial of service, caused by a memory corruption error related to missing range checks on file descriptors being used in the "FD_SET" macro. By performing a select on a bad file descriptor set, a remote attacker could exploit this vulnerability to cause the application to crash or possibly execute arbitrary code on the system.</p> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2011-0719</cvename> + <url>http://www.samba.org/samba/security/CVE-2011-0719.html</url> + <url>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0719</url> + </references> + <dates> + <discovery>2011-02-28</discovery> + <entry>2011-06-01</entry> + </dates> + </vuln> + <vuln vid="1acf9ec5-877d-11e0-b937-001372fd0af2"> <topic>drupal6 -- multiple vulnerabilities</topic> <affects> --FL5UXtIhxfXey3p5--
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20110602013844.GA30119>